Privacy Policy

Your data, and only what we need.

Polyrez stores the résumé data you give it so it can render your Rézi, and nothing that tracks you. There is no analytics, no advertising and no third-party script in the app. This page lists what we keep, where, for how long, and how to get it out or have it deleted.

Who we are

Polyrez (polyrez.app) is operated from New South Wales, Australia (ABN ABN 64 257 676 141). Questions about this policy or your data go to [email protected].

What we store

  • Account details: your email address and name, and a profile picture URL if your sign-in provider supplies one. If you sign in with GitHub or Google we keep the provider's account id for you; if you use a password we keep only a salted hash of it, never the password itself.
  • Your résumé content: your master YAML and the YAML of every Réz, their titles, tags and theme choices, and a version history of entries so you can compare and restore earlier wording.
  • Rendered output: the PDFs we render for you, their thumbnails and the render logs.
  • Assets you upload, such as a photo or a logo.
  • GitHub sync data, if you connect a repository: the GitHub App installation id, the repository you chose, and records of each sync. The files we commit are your own Rézi.
  • Billing references: your Stripe customer id, subscription id, plan, subscription status and renewal date. We never see or store your card number.
  • Sign-in sessions: a session cookie that keeps you signed in, and single-use tokens for sign-in or password-reset links while they are valid.

We do not use analytics, tracking pixels, advertising networks or third-party SDKs. Fonts are served from our own server. Our server logs record request metadata and internal ids for debugging; they do not contain your résumé text or your PDFs.

Where it lives

Everything above is stored on a virtual private server in Sydney, Australia, which we administer ourselves. Rendering happens on the same server.

Who else processes it

  • Stripe processes payments. When you check out, you give your payment details to Stripe directly, under Stripe's privacy policy. Stripe tells us whether a payment succeeded and sends us the ids listed above.
  • GitHub and Google handle sign-in if you choose them, and GitHub hosts any repository you connect for sync.
  • Email: sign-in and password-reset messages are sent to your address from our own mail server.

We do not sell your data or share it with anyone else.

Sharing links

If you share a Réz, anyone with its link can view that Réz until you stop sharing it. Nothing is public unless you share it.

How long we keep it

We keep your data while your account exists. Rendered PDFs and thumbnails may be regenerated or discarded at any time, because they can be rebuilt from your YAML. After your trial or subscription ends your account becomes read-only, but nothing is deleted: you can still view and download every Réz. Backup retention: [backup retention period to be confirmed].

Export and deletion

You can download all of your Rézi and source files at any time from the app. Self-service account deletion is not built yet; until it is, email [email protected] from the address on your account and we will delete your account and its data, and confirm by reply. Billing records that Stripe or tax law require to be kept are held by Stripe, not by us.

Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, by emailing [email protected]. We aim to handle personal information consistently with the Australian Privacy Principles. If you are unhappy with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

Changes

If we change what we collect or who processes it, we will update this page and the date below before the change takes effect. See also the Terms and the Refund Policy.

Draft, last updated 26 September 2026. Not yet reviewed by a lawyer.